Oracle disclosed a critical (CVSS 9.8) flaw in Oracle Coherence that lets an unauthenticated attacker with network access fully compromise the product over TCP.
What Is It
CVE-2026-60302 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks can result in complete takeover of Oracle Coherence.
The CVSS 3.1 base score is 9.8 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning network attack vector, low complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of no authentication, low attack complexity, network reachability, and a full-takeover outcome makes this among the most severe classes of vulnerability. An attacker who can reach an exposed Coherence instance over TCP can seize control without credentials or user interaction, threatening the confidentiality, integrity, and availability of the affected system.
Note: The supplied CISA KEV entry is empty, so there is no confirmation of active exploitation at this time.
What's Vulnerable
Per the NVD record, the affected supported versions of Oracle Coherence (Oracle Corporation) are:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
Oracle addressed this issue in its July 2026 Critical Patch Update. Organizations running any affected version should apply the fixes referenced in the Oracle Critical Patch Update Advisory (July 2026). No separate CISA KEV required-action or due date was supplied in the source material.
Sources
- Oracle Critical Patch Update Advisory - July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60302, https://nvd.nist.gov/vuln/detail/CVE-2026-60302